chiprook
← Security
SecuritySeptember 27, 2026, 22:49

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI plugins

Air Security researchers found Plugin4Shell, a zero-click RCE in the plugin marketplaces of Claude Code, OpenAI Codex, GitHub Copilot and Google Gemini CLI: agents run git checkout on a pinned SHA without verifying the code matches that commit. One PoC plugin spread to over 26,000 agents, while the SkillJacking campaign compromised 925 skills and 134,000 agents. Anthropic and OpenAI shipped fixes, Google deprecated Gemini CLI, and Copilot had no patch at disclosure.

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI plugins
#Anthropic#OpenAI#GitHub#Google
Read next
Security

Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents

Security

1,145-star CLI promised local-only operation, executed hidden payload at import

AI

GitHub Copilot CLI gets HydraFusion multi-model routing

Policy

Coders lose their DMCA case against GitHub Copilot and Codex